Privacy Policy

Effective date: August 2, 2026 · Version 2026-08-02

This Privacy Policy describes how Company, LLC (“Company,” “we,” “us,” or “SNFY”) collects, uses, and shares information in connection with the SNFY web application and related services (the “Service”). This Policy is intended for business customers and their Authorized Users.

Protected Health Information (PHI). When we process PHI on behalf of a customer, that processing is governed by our Business Associate Agreement and applicable HIPAA requirements, not solely by this Policy. This Policy focuses on account, usage, and other personal information about Authorized Users and business contacts.

1. Information we collect

  • Account information. Name, work email, role, organization or management group affiliation, and authentication data (for example, one-time passcodes and session tokens).
  • Billing information. Billing email, payment method metadata (such as last four digits, account holder name, and payment rail), and related invoices. Full payment credentials are handled by our payment processor when tokenization is enabled.
  • Customer content. Claim, facility, payer, and workflow data that customers upload or generate in the Service. That content may include PHI and is handled under the BAA.
  • Usage and device data. Log data such as IP address, browser/user agent, approximate timestamps, pages viewed, and diagnostic events needed to operate and secure the Service.
  • Communications. Support requests, feedback, and other messages you send us.

2. How we use information

We use information to:

  • provide, maintain, and improve the Service;
  • authenticate users and enforce role-based access;
  • bill and collect Fees;
  • provide customer support and send service-related notices;
  • secure the Service, detect abuse, and maintain HIPAA-aligned audit trails (including append-only audit logs with long retention);
  • comply with law and enforce our Terms of Service; and
  • create de-identified or aggregated insights that do not identify individuals or a specific customer.

3. Cookies and authentication

We use necessary cookies and similar technologies to maintain authenticated sessions and security preferences. We do not use third-party advertising cookies in the Service. You can control cookies through your browser, but disabling necessary cookies may prevent sign-in.

4. How we share information

We may share information with:

  • Service providers / subprocessors that host or help operate the Service (for example, cloud database/auth hosting, payment processing, email delivery, and clearinghouse or payer-portal integrations used at a customer's direction). These providers are bound by contractual confidentiality and, where they handle PHI, business associate or equivalent terms as applicable.
  • Customer administrators within the same management group or organization, consistent with roles and permissions configured in the Service.
  • Legal and safety disclosures when Required by Law, to protect rights and security, or in connection with a merger, acquisition, or asset sale (with appropriate protections).

We do not sell personal information.

5. Retention

We retain account and billing records for as long as the customer relationship lasts and as needed for legal, tax, and audit purposes. HIPAA-related audit logs are retained for at least six (6) years (or longer if Required by Law). PHI retention and return/destruction follow the BAA. When data is no longer needed, we delete or de-identify it according to our retention practices.

6. Security

We implement administrative, technical, and physical safeguards appropriate to the nature of the Service, including encryption in transit, access controls, and audit logging. No method of transmission or storage is completely secure; please contact us promptly if you believe your account has been compromised.

7. Your choices

Authorized Users may update certain profile information in the Service. To request access, correction, or deletion of personal information about an Authorized User (to the extent applicable under law and not overridden by HIPAA or legal retention duties), contact your organization administrator or Company, LLC via the support channels in the Service. We may need to verify the request and will respond as required by applicable law.

8. Children

The Service is a business application and is not directed to children under 13 (or the age required by local law). We do not knowingly collect personal information from children in that category as end users of the Service.

9. International transfers

The Service is operated for customers in the United States. If you access the Service from another country, you understand that information may be processed in the United States, which may have different data-protection rules.

10. Changes

We may update this Privacy Policy from time to time. We will post the updated Policy with a new effective date and version. Material changes will be communicated through the Service or by email to administrators where appropriate.

11. Contact

Privacy questions: contact Company, LLC using the support channels provided in the Service.

Related: Terms of Service · Business Associate Agreement · Pricing Schedule